Bump the github-actions group with 12 updates
Bumps the github-actions group with 12 updates: | Package | From | To | | --- | --- | --- | | [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) | `3.7.0` | `4.0.0` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.12.0` | `4.0.0` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.22.1` | `0.24.0` | | [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) | `6.4.0` | `7.0.0` | | [anchore/scan-action](https://github.com/anchore/scan-action) | `7.3.1` | `7.4.0` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `6` | `7` | | [actions/download-artifact](https://github.com/actions/download-artifact) | `6` | `8` | | [docker/setup-compose-action](https://github.com/docker/setup-compose-action) | `1.2.0` | `2.1.0` | | [docker/login-action](https://github.com/docker/login-action) | `3.7.0` | `4.0.0` | | [actions/attest-sbom](https://github.com/actions/attest-sbom) | `3` | `4` | | [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) | `3` | `4` | | [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) | `b78fbfd8eb982f4802e09a265fb2bc37b3040975` | `e48f9039c82786db50685e8ef7d980b209f06186` | Updates `docker/setup-qemu-action` from 3.7.0 to 4.0.0 - [Release notes](https://github.com/docker/setup-qemu-action/releases) - [Commits](c7c5346462...ce360397dd) Updates `docker/setup-buildx-action` from 3.12.0 to 4.0.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](8d2750c68a...4d04d5d948) Updates `anchore/sbom-action` from 0.22.1 to 0.24.0 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](deef08a0db...e22c389904) Updates `goreleaser/goreleaser-action` from 6.4.0 to 7.0.0 - [Release notes](https://github.com/goreleaser/goreleaser-action/releases) - [Commits](e435ccd777...ec59f474b9) Updates `anchore/scan-action` from 7.3.1 to 7.4.0 - [Release notes](https://github.com/anchore/scan-action/releases) - [Changelog](https://github.com/anchore/scan-action/blob/main/RELEASE.md) - [Commits](8d2fce0942...e1165082ff) Updates `actions/upload-artifact` from 6 to 7 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](https://github.com/actions/upload-artifact/compare/v6...v7) Updates `actions/download-artifact` from 6 to 8 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](https://github.com/actions/download-artifact/compare/v6...v8) Updates `docker/setup-compose-action` from 1.2.0 to 2.1.0 - [Release notes](https://github.com/docker/setup-compose-action/releases) - [Commits](364cc21a5d...8cccb8c14b) Updates `docker/login-action` from 3.7.0 to 4.0.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](c94ce9fb46...b45d80f862) Updates `actions/attest-sbom` from 3 to 4 - [Release notes](https://github.com/actions/attest-sbom/releases) - [Changelog](https://github.com/actions/attest-sbom/blob/main/RELEASE.md) - [Commits](https://github.com/actions/attest-sbom/compare/v3...v4) Updates `actions/attest-build-provenance` from 3 to 4 - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](https://github.com/actions/attest-build-provenance/compare/v3...v4) Updates `trufflesecurity/trufflehog` from b78fbfd8eb982f4802e09a265fb2bc37b3040975 to e48f9039c82786db50685e8ef7d980b209f06186 - [Release notes](https://github.com/trufflesecurity/trufflehog/releases) - [Commits](b78fbfd8eb...e48f9039c8) --- updated-dependencies: - dependency-name: docker/setup-qemu-action dependency-version: 4.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/setup-buildx-action dependency-version: 4.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: anchore/sbom-action dependency-version: 0.24.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: goreleaser/goreleaser-action dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: anchore/scan-action dependency-version: 7.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/upload-artifact dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/download-artifact dependency-version: '8' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/setup-compose-action dependency-version: 2.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/login-action dependency-version: 4.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/attest-sbom dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/attest-build-provenance dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: trufflesecurity/trufflehog dependency-version: e48f9039c82786db50685e8ef7d980b209f06186 dependency-type: direct:production dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
This commit is contained in:
committed by
Sacha Al Himdani
parent
d86bce1a59
commit
e6b88e7eec
30
.github/workflows/make.yaml
vendored
30
.github/workflows/make.yaml
vendored
@@ -32,8 +32,8 @@ jobs:
|
||||
cache: "npm"
|
||||
- run: "npm i -g npm@11.8.0"
|
||||
- run: "npm ci"
|
||||
- uses: "docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130" # v3.7.0
|
||||
- uses: "docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f" # v3.12.0
|
||||
- uses: "docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a" # v4.0.0
|
||||
- uses: "docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd" # v4.0.0
|
||||
- uses: "sigstore/cosign-installer@053f9b74638557590800a301da1ba82351507e2c" # v3.8.1
|
||||
- name: Cache Trivy database
|
||||
uses: "actions/cache@v5"
|
||||
@@ -42,8 +42,8 @@ jobs:
|
||||
key: trivy-db-${{ runner.os }}-${{ github.run_id }}
|
||||
restore-keys: |
|
||||
trivy-db-${{ runner.os }}-
|
||||
- uses: "anchore/sbom-action/download-syft@deef08a0db64bfad603422135db61477b16cef56" # v0.22.1
|
||||
- uses: "goreleaser/goreleaser-action@e435ccd777264be153ace6237001ef4d979d3a7a" # v6.4.0
|
||||
- uses: "anchore/sbom-action/download-syft@e22c389904149dbc22b58101806040fa8d37a610" # v0.24.0
|
||||
- uses: "goreleaser/goreleaser-action@ec59f474b9834571250b370d4735c50f8e2d1e29" # v7.0.0
|
||||
with:
|
||||
distribution: "goreleaser"
|
||||
version: "~> v2"
|
||||
@@ -78,12 +78,12 @@ jobs:
|
||||
uses: github/codeql-action/upload-sarif@6bc82e05fd0ea64601dd4b465378bbcf57de0314 # v4.32.1
|
||||
with:
|
||||
sarif_file: "trivy-results.sarif"
|
||||
- uses: anchore/sbom-action@deef08a0db64bfad603422135db61477b16cef56 #v0.22.1
|
||||
- uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 #v0.24.0
|
||||
with:
|
||||
path: ./
|
||||
format: cyclonedx-json
|
||||
output-file: sbom.json
|
||||
- uses: anchore/scan-action@8d2fce09422cd6037e577f4130e9b925e9a37175 #v7.3.1
|
||||
- uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 #v7.4.0
|
||||
with:
|
||||
sbom: "sbom.json"
|
||||
fail-build: true
|
||||
@@ -111,7 +111,7 @@ jobs:
|
||||
- run: "npm i -g npm@11.8.0"
|
||||
- run: "npm ci"
|
||||
- run: "make build"
|
||||
- uses: "actions/upload-artifact@v6"
|
||||
- uses: "actions/upload-artifact@v7"
|
||||
with:
|
||||
name: "build-artifacts"
|
||||
path: |
|
||||
@@ -148,7 +148,7 @@ jobs:
|
||||
- uses: reviewdog/action-setup@d8a7baabd7f3e8544ee4dbde3ee41d0011c3a93f # v1.5.0
|
||||
- run: "npm i -g npm@11.8.0"
|
||||
- run: "npm ci"
|
||||
- uses: "actions/download-artifact@v6"
|
||||
- uses: "actions/download-artifact@v8"
|
||||
with:
|
||||
name: "build-artifacts"
|
||||
- run: "chmod +x bin/probod"
|
||||
@@ -195,7 +195,7 @@ jobs:
|
||||
go-version: "1.26.1"
|
||||
cache: true
|
||||
- run: "go mod download"
|
||||
- uses: "actions/download-artifact@v6"
|
||||
- uses: "actions/download-artifact@v8"
|
||||
with:
|
||||
name: "build-artifacts"
|
||||
- run: "chmod +x bin/probod"
|
||||
@@ -204,14 +204,14 @@ jobs:
|
||||
env:
|
||||
GOTESTSUM_JUNITFILE: "junit.xml"
|
||||
- name: "Upload test results"
|
||||
uses: "actions/upload-artifact@v6"
|
||||
uses: "actions/upload-artifact@v7"
|
||||
if: "always()"
|
||||
with:
|
||||
name: "junit-results"
|
||||
path: "junit.xml"
|
||||
retention-days: 30
|
||||
- run: "make coverage-report"
|
||||
- uses: "actions/upload-artifact@v6"
|
||||
- uses: "actions/upload-artifact@v7"
|
||||
with:
|
||||
name: "coverage-reports"
|
||||
path: |
|
||||
@@ -249,9 +249,9 @@ jobs:
|
||||
- run: "npm i -g npm@11.8.0"
|
||||
- run: "sudo apt-get install -y mkcert"
|
||||
- run: "sudo mkcert -install 2>&1 | grep -v 'no Firefox and/or Chrome/Chromium security databases found' || true"
|
||||
- uses: "docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130" # v3.7.0
|
||||
- uses: "docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f" # v3.12.0
|
||||
- uses: "docker/setup-compose-action@364cc21a5de5b1ee4a7f5f9d3fa374ce0ccde746" # v1.2.0
|
||||
- uses: "docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a" # v4.0.0
|
||||
- uses: "docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd" # v4.0.0
|
||||
- uses: "docker/setup-compose-action@8cccb8c14b6500aaffebff1aa49c502c34d2e5e6" # v2.1.0
|
||||
- run: "npm ci"
|
||||
- run: "make stack-up"
|
||||
- run: "make stack-ps"
|
||||
@@ -276,7 +276,7 @@ jobs:
|
||||
env:
|
||||
GOTESTSUM_JUNITFILE: "junit-e2e.xml"
|
||||
- name: "Upload test results"
|
||||
uses: "actions/upload-artifact@v6"
|
||||
uses: "actions/upload-artifact@v7"
|
||||
if: "always()"
|
||||
with:
|
||||
name: "junit-e2e-results"
|
||||
|
||||
30
.github/workflows/release.yaml
vendored
30
.github/workflows/release.yaml
vendored
@@ -54,22 +54,22 @@ jobs:
|
||||
run: cosign initialize
|
||||
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
|
||||
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0
|
||||
|
||||
- name: Set up QEMU
|
||||
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3.7.0
|
||||
uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4.0.0
|
||||
with:
|
||||
platforms: all
|
||||
|
||||
- name: Log in to GitHub Container Registry
|
||||
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0
|
||||
uses: docker/login-action@b45d80f862d83dbcd57f89517bcf500b2ab88fb2 # v4.0.0
|
||||
with:
|
||||
registry: ghcr.io
|
||||
username: ${{ github.actor }}
|
||||
password: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
- name: Run GoReleaser
|
||||
uses: goreleaser/goreleaser-action@e435ccd777264be153ace6237001ef4d979d3a7a # v6.4.0
|
||||
uses: goreleaser/goreleaser-action@ec59f474b9834571250b370d4735c50f8e2d1e29 # v7.0.0
|
||||
with:
|
||||
distribution: goreleaser
|
||||
version: "~> v2"
|
||||
@@ -96,14 +96,14 @@ jobs:
|
||||
sarif_file: "trivy-results.sarif"
|
||||
|
||||
- name: Generate SBOM
|
||||
uses: anchore/sbom-action@deef08a0db64bfad603422135db61477b16cef56 #v0.22.1
|
||||
uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 #v0.24.0
|
||||
with:
|
||||
path: ./
|
||||
format: cyclonedx-json
|
||||
output-file: sbom.json
|
||||
|
||||
- name: Run vulnerability scan
|
||||
uses: anchore/scan-action@8d2fce09422cd6037e577f4130e9b925e9a37175 #v7.3.1
|
||||
uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 #v7.4.0
|
||||
with:
|
||||
sbom: "sbom.json"
|
||||
fail-build: true
|
||||
@@ -122,13 +122,13 @@ jobs:
|
||||
echo "hashes=$(cat checksums.txt | base64 -w0)" >> "$GITHUB_OUTPUT"
|
||||
|
||||
- name: Attest SBOM
|
||||
uses: actions/attest-sbom@v3
|
||||
uses: actions/attest-sbom@v4
|
||||
with:
|
||||
subject-path: "dist/*.tar.gz, dist/*.zip"
|
||||
sbom-path: "sbom.json"
|
||||
|
||||
- name: Attest build provenance
|
||||
uses: actions/attest-build-provenance@v3
|
||||
uses: actions/attest-build-provenance@v4
|
||||
with:
|
||||
subject-path: "dist/*.tar.gz, dist/*.zip"
|
||||
|
||||
@@ -141,14 +141,14 @@ jobs:
|
||||
echo "digest=$DIGEST" >> "$GITHUB_OUTPUT"
|
||||
|
||||
- name: Attest Docker image SBOM
|
||||
uses: actions/attest-sbom@v3
|
||||
uses: actions/attest-sbom@v4
|
||||
with:
|
||||
subject-name: "ghcr.io/getprobo/probo"
|
||||
subject-digest: ${{ steps.image.outputs.digest }}
|
||||
sbom-path: "sbom.json"
|
||||
|
||||
- name: Upload SBOM as artifact
|
||||
uses: actions/upload-artifact@v6
|
||||
uses: actions/upload-artifact@v7
|
||||
with:
|
||||
name: sbom
|
||||
path: |
|
||||
@@ -183,13 +183,13 @@ jobs:
|
||||
VERSION="${GITHUB_REF_NAME#v}"
|
||||
npm --workspace @probo/n8n-nodes-probo version "$VERSION" --no-git-tag-version
|
||||
|
||||
- uses: anchore/sbom-action@deef08a0db64bfad603422135db61477b16cef56 #v0.22.1
|
||||
- uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 #v0.24.0
|
||||
with:
|
||||
path: ./packages/n8n-node
|
||||
format: cyclonedx-json
|
||||
output-file: packages/n8n-node/sbom.json
|
||||
|
||||
- uses: anchore/scan-action@8d2fce09422cd6037e577f4130e9b925e9a37175 #v7.3.1
|
||||
- uses: anchore/scan-action@e1165082ffb1fe366ebaf02d8526e7c4989ea9d2 #v7.4.0
|
||||
with:
|
||||
path: ./packages/n8n-node
|
||||
fail-build: true
|
||||
@@ -207,16 +207,16 @@ jobs:
|
||||
- run: npm --workspace @probo/n8n-nodes-probo publish --access public --dry-run
|
||||
- run: npm --workspace @probo/n8n-nodes-probo publish --access public
|
||||
|
||||
- uses: actions/attest-sbom@v3
|
||||
- uses: actions/attest-sbom@v4
|
||||
with:
|
||||
subject-path: "packages/n8n-node/dist/**"
|
||||
sbom-path: "packages/n8n-node/sbom.json"
|
||||
|
||||
- uses: actions/attest-build-provenance@v3
|
||||
- uses: actions/attest-build-provenance@v4
|
||||
with:
|
||||
subject-path: "packages/n8n-node/dist/**"
|
||||
|
||||
- uses: actions/upload-artifact@v6
|
||||
- uses: actions/upload-artifact@v7
|
||||
with:
|
||||
name: npm-sbom
|
||||
path: |
|
||||
|
||||
2
.github/workflows/secrets.yaml
vendored
2
.github/workflows/secrets.yaml
vendored
@@ -17,6 +17,6 @@ jobs:
|
||||
with:
|
||||
fetch-depth: 0
|
||||
submodules: recursive
|
||||
- uses: "trufflesecurity/trufflehog@b78fbfd8eb982f4802e09a265fb2bc37b3040975" # main
|
||||
- uses: "trufflesecurity/trufflehog@e48f9039c82786db50685e8ef7d980b209f06186" # main
|
||||
with:
|
||||
extra_args: "--results=verified,unknown --exclude-paths=.trufflehog-exclude"
|
||||
|
||||
Reference in New Issue
Block a user